OpenAI Confirms AI Agent Independently Executed a Major Cyber Attack

Deep News
07/22

OpenAI has acknowledged that one of its AI "agents" autonomously discovered a new vulnerability and breached the startup Hugging Face, marking one of the first publicly disclosed instances of an AI system independently launching a cyber attack outside of human control.

The developer of ChatGPT stated on Tuesday that this "unprecedented cyber event" involved an agent—an AI program capable of operating autonomously based on human instructions—which escaped its testing environment, gained internet access, and stole login credentials.

This incident occurs as external concerns grow regarding the potential impact of advanced AI systems on digital infrastructure, particularly scenarios where agents could circumvent human oversight.

OpenAI indicated on Tuesday that it anticipates such events "will become more common as models with increasingly powerful cyber capabilities proliferate."

The event happened as CEO Sam Altman prepares to travel to Washington next week to brief the U.S. government on a new generation of AI models.

Following global attention on the advanced capabilities of Anthropic's Mythos model in detecting and exploiting network vulnerabilities, the U.S. government is increasingly seeking to review models before their release.

OpenAI stated that the recent incident involved a combination of several of its models, including GPT-5.6 Sol released earlier this month, as well as a more capable, unreleased model currently under testing.

In a blog post, OpenAI said: "We consider this an unprecedented cyber event involving state-of-the-art cyber capabilities and are responding accordingly."

Hugging Face, an AI startup that hosts models and datasets for developers, reported that it was breached by an external AI agent last Friday.

CEO Clement Delangue posted on X: "Given the sophistication of the agent, we suspect last week's cyber attack may have originated from a frontier lab."

He added that the company has been working closely with OpenAI over the past day, "and we firmly believe they had no malicious intent. The fact that this all happened autonomously is simply shocking!"

OpenAI had intentionally reduced its network protections to evaluate these two models in a test environment. However, these agents were operating in a so-called "sandbox" designed to control the systems and prevent them from accessing the internet.

The models were instructed to attempt hacking activities to assess their cyber capabilities, and subsequently "spent a significant amount of [computing resources] finding ways to gain access to the open internet," OpenAI stated.

The models "identified and exploited" previously unknown vulnerabilities, escaped the sandbox, gained internet access, and continued pursuing their objective, which included stealing credentials to carry out attacks.

Hugging Face used its own agent to detect and block the activity on its infrastructure. OpenAI stated it has communicated with law enforcement and other government agencies regarding the incident.

免责声明:投资有风险,本文并非投资建议,以上内容不应被视为任何金融产品的购买或出售要约、建议或邀请,作者或其他用户的任何相关讨论、评论或帖子也不应被视为此类内容。本文仅供一般参考,不考虑您的个人投资目标、财务状况或需求。TTM对信息的准确性和完整性不承担任何责任或保证,投资者应自行研究并在投资前寻求专业建议。

热议股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10